Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Jan 2004
    Posts
    30

    Default is this a hacker ?

    Hi,

    My server has been showing high loads at various times over the past few days.
    I checked my logs, and found some strange information. I'm not sure if this is a hacking attempt, or if they in fact have gained access, or whether somebody is using a script to try and gain access.

    This is a snapshot taken from my ACCESS_LOG file:
    ####################

    218.232.96.150 - - [31/Jan/2006:18:47:47 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:47 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:48 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:48 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /blog/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /drupal/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:49 -0500] "GET /community/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /blogs/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /blog/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /blogs/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:50 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /drupal/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /blog/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /community/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /blogtest/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /blogs/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:51 -0500] "GET /b2/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /blog/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /blogs/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /b2evo/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /drupal/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /blog/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /wordpress/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:52 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /community/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /xmlrpc/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /blogtest/xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /phpgroupware/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /blog/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /x0x0x0x0x0x0x0x0x0/ThisFileMustNotExist HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /blogs/xmlrpc.php HTTP/1.0" 404 137
    218.232.96.150 - - [31/Jan/2006:18:47:53 -0500] "GET /xmlsrv/xmlrpc.php HTTP/1.0" 404 137
    ##################
    This is only a PART of it as the post would not allow the full amount!

    This type of stuff has been appearing frequently over the last couple of weeks. The problem is, it is from a variety of different IP addresses. I don;t know if this is some type of DDOS attack, a hacker using a proxy or what.

    Anybody any suggestions ?

  2. #2
    Member
    Join Date
    Apr 2003
    Posts
    479

    Default

    More likely it's a worm on multiple servers.


    Something like this:
    http://securityresponse.symantec.com...ux.plupii.html

  3. #3
    Member
    Join Date
    Nov 2005
    Posts
    97

    Default

    You should make use of your Mod_Sec and apply some 'GET" rules.

  4. #4
    Member
    Join Date
    Jan 2004
    Posts
    30

    Default

    Hi,

    Okay I ran chkrootkit and it came up with the following:

    Checking `bindshell'... INFECTED (PORTS: 465)


    I'm not too hot on this subject, so how would I go about treating this?

    I have AFP installed on ther server, and I don't think 465 is a common port so how it got infected is a mystery. But the problem is fixing it, how would I go about that?

  5. #5
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    It's a false-positive. Port 465 is used for ssmtp (SMTP over SSL).
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

Similar Threads & Tags
Similar threads

  1. Hacker?? Need help
    By ChipW in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 06-12-2007, 02:42 AM
  2. I have been hacker attack
    By caykoylu in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 12-01-2006, 07:47 PM
  3. Crazy hacker.......
    By amal in forum cPanel and WHM Discussions
    Replies: 14
    Last Post: 05-09-2005, 10:58 PM
  4. hacker report
    By mahdionline in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 10-17-2004, 04:18 PM
  5. Is this a hacker??
    By hjnet in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 05-31-2002, 06:17 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube